VDB
Sign up
MEDIUM

GHSA-pxmp-fwjc-4x7q

HTML Injection in marky-markdown

Details

All versions of `marky-markdown` are vulnerable to HTML Injection due to a validation bypass. The package only allows iframes where the source is `youtube.com` but it is possible to bypass the validation with sources where `youtube.com` is the sub-domain, such as `youtube.com.evil.co`. This

## Recommendation

This package is no longer maintained. Please upgrade to `@npmcorp/marky-markdown`

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/marky-markdown
Introduced in: 0.0.0

No fixed version published yet for marky-markdown (npm). Pin to a known-safe version or switch to an alternative.

References